咨询:能否配置Grafana LDAP组关联Orgs/Teams实现新用户自动归属
Absolutely! You can map LDAP groups to Grafana organizations (Orgs) and teams, so new users from those LDAP groups get automatically added to the corresponding Orgs/Teams on their first login. Let me break down how to set this up for both scenarios:
This is handled directly in Grafana's LDAP configuration file (usually located at conf/ldap.toml). Here's how to configure it:
First, ensure your LDAP server attributes are correctly set
In the[servers.attributes]section, make sure you've defined the attribute that holds group memberships (most commonlymemberOf):[servers.attributes] name = "givenName" surname = "sn" username = "sAMAccountName" member_of = "memberOf" # This is key for group mappings email = "mail"Add group-to-organization mappings
Under the[servers.group_mappings]section, create entries that link LDAP groups to specific Grafana organizations and roles. For example:[[servers.group_mappings]] group_dn = "cn=grafana-admins,ou=groups,dc=example,dc=com" org_role = "Admin" org_id = 1 # Replace with your target organization's ID [[servers.group_mappings]] group_dn = "cn=grafana-editors,ou=groups,dc=example,dc=com" org_role = "Editor" org_id = 1 [[servers.group_mappings]] group_dn = "cn=grafana-viewers,ou=groups,dc=example,dc=com" org_role = "Viewer" org_id = 2 # Map to a different organizationgroup_dn: The full Distinguished Name of your LDAP grouporg_role: The role the user will get in the organization (options:Admin,Editor,Viewer)org_id: The numeric ID of the Grafana organization you want to link to
When a new user from these LDAP groups logs in for the first time, Grafana will automatically create their account and add them to the specified organization with the assigned role.
For team mappings, you'll use Grafana's provisioning feature (since LDAP config alone doesn't handle team sync). Here's the step-by-step:
Create a team provisioning file
Navigate to the provisioning teams directory (default:conf/provisioning/teams/) and create a YAML file (e.g.,ldap-team-sync.yaml). Add content like this:apiVersion: 1 teams: - name: "Data Engineering Team" uid: "data-eng-team" orgId: 1 # Must match the organization ID where the team exists members: - query: "memberOf=cn=data-engineers,ou=groups,dc=example,dc=com" group: "LDAP" - name: "DevOps Team" uid: "devops-team" orgId: 1 members: - query: "memberOf=cn=devops,ou=groups,dc=example,dc=com" group: "LDAP"name: The name of your Grafana teamuid: A unique identifier for the team (used to avoid duplicates during provisioning)orgId: The organization ID the team belongs toquery: The LDAP group membership filter (matches users in the specified LDAP group)group: "LDAP": Tells Grafana to sync users from the LDAP group into this team
Verify provisioning is enabled
Check yourconf/defaults.ini(or customconf/custom.ini) to ensure team provisioning is turned on:[provisioning] teams = trueRestart Grafana
After saving the provisioning file, restart your Grafana server to apply the changes.
From now on, any user in the mapped LDAP groups (whether new or existing) will be automatically added to the corresponding Grafana team on their next login.
- Always back up your configuration files before making changes.
- For existing users, their organization roles and team memberships will update on their next login after you modify the LDAP/provisioning configs.
- You can combine both methods (Org and Team mappings) to fully automate user access based on LDAP groups.
内容的提问来源于stack exchange,提问作者ScipioAfricanus

